Click to Play

Low-Cost Search Tactics
Although search marketing is not known as being an extremely expensive marketing endeavor, it still takes some monetary resources. Not every small mom-n-pop..

Recent Articles

Learning Malware Lessons From Web Hosting In...
I've been paying a lot more attention to the problem of malware. It seems that this issue may be set to be the largest threat to online business, and given the sheer volume of new attacks I thought it would...

Cloud Computing Worst Practices And How To...
It is no surprise that many IT organizations are struggling to implement enterprise solutions in the cloud. After all, we have seen IT struggle for decades with many "new" initiatives like SOA, ERP...

Intuit Blurs The Lines Between Open Source...
The lines between open source and proprietary vendors' software strategies continue to blur. Intuit announced the launch of a community site for developers interested in creating connected on line applications for...

Google's Next Microsoft Killer Chrome OS
Yep - it's true. Google are venturing into the world of computer operating systems and have clearly put Microsoft on notice. In case you missed the news, last week Google confirmed that they will be...


09.08.09

Keeping Your WordPress Blog Secure From Hackers

By Neville Hobson

If you use self-hosted WordPress for your blog and you're not using the latest version, 2.8.4, you're running a severe risk of your site security being compromised and even hacked. So do these three things right now:

1. Log in to your WordPress admin dashboard and check what version of WordPress you have installed. If you're running any version higher than 2.7, you'll see a text like this in the ‘Right Now' module at the top of your screen (if you don't see that module, check your screen options settings):

youareusingwp284

2. Change all your passwords including admin, for each user if you have multiple users and FTP access. Then check the list of users to see if there are any you don't recognize. If so, remove them.

3. If the version text on your dashboard says anything other than "You are using WordPress 2.8.4," you'll need to upgrade. You can do it from within your WordPress admin if you're using a recent version (if you're not, then you really are at risk). Or check your hosting service to see if they offer an easy upgrade method, eg, like 1-Click, the simple and secure method offered by DreamHost, my hosting service, or something like  Fantastico offered by many others.

Earn Your Bachelor's Degree Online
in Internet Marketing - Click Here

If you do have to upgrade, by whatever method you use, please still follow the detailed how-to guide in the WordPress Codex, the detailed documentation system for all things WordPress, paying special attention to the prep you need to do before you execute the upgrade.

Or, check out my 6 tips for upgrading WordPress including the 10-minute audio guide.

It never ceases to surprise me how some bloggers don't upgrade (I've been guilty, too). Yes, it can be inconvenient and a bit time consuming especially if you rigorously do the prep including disabling all plugins.

Yet the consequences for not doing it can be catastrophe. So it's worth the time invested.

If you are interested in the details of exactly what this security issue is all about, including the tell-tale signs that suggest your site may have been compromised, read Lorelle VanFossen's post with the alert about this issue. She also has links to some terrific resources on how to strengthen your blog security.

Stay secure!

Comments


About the Author:
Neville Hobson is the author of the popular NevilleHobson.com blog which focuses on business communication and technology.

Neville is a UK-based communicator, blogger and podcaster. He helps companies use effective communication to achieve their business goals. Visit Neville Hobson's blog: NevilleHobson.com.
About ITProNews
News and updates for the IT professional





ITProNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
PerlProNews.com SQLProNews.com
SysAdminNews DevWebPro.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITCertificationNews.com






-- ITProNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
©2009 iEntry, Inc. All Rights Reserved Privacy Policy Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


ITProNews News Archives About Us Feedback ITProNews Home Page About Article Archive News Downloads WebProWorld Forums Jayde iEntry Advertise Contact